command-line-murders/i-00baa51fad562d866
by SadServersMore by SadServers
u=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;336:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36: PROMPT_COMMAND=history -a;history -c;history -r; INVOCATION_ID=f9fa28799c9b4a0589d2be76c4f0c627 TERM=xterm-256color USER=admin SHLVL=2 JOURNAL_STREAM=8:11349 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin _=/usr/bin/env admin@i-058021c251bc777a6:~$ ls -l total 8 drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-058021c251bc777a6:~$ cd a
paris/i-058021c251bc777a6 01:39
by SadServersroot 579 1 0 10:14 ttyS0 00:00:00 /sbin/agetty -o -p -- \u --k_chrony 589 1 0 10:14 ? 00:00:00 /usr/sbin/chronyd -F 1 root 590 1 0 10:14 ? 00:00:00 sshd: /usr/sbin/sshd -D [lis_chrony 591 589 0 10:14 ? 00:00:00 /usr/sbin/chronyd -F 1 root 598 1 0 10:14 ? 00:00:00 /usr/bin/python3 /usr/share/root 678 2 0 10:14 ? 00:00:00 [kworker/0:3-events] root 679 2 0 10:14 ? 00:00:00 [kworker/0:4-mm_percpu_wq] admin 796 561 0 10:18 pts/0 00:00:00 bash -l admin 800 796 0 10:18 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asadmin 803 800 0 10:18 pts/0 00:00:00 /usr/bin/python3 /usr/bin/asadmin 804 800 0 10:18 pts/1 00:00:00 sh -c /bin/bash admin 805 804 0 10:18 pts/1 00:00:00 /bin/bash root 843 2 0 10:19 ? 00:00:00 [kworker/u4:2-events_unboundadmin 846 805 0 10:19 pts/1 00:00:00 ps -ef admin@i-01ba3fb0890c35be2:~$
paris/i-01ba3fb0890c35be2 01:11
by SadServersa.out agent webserver.py $ admin@i-072b43453825ba99a:~$ find / -perm -u=s -type f 2>/dev/null /usr/lib/openssh/ssh-keysign /usr/lib/dbus-1.0/dbus-daemon-launch-helper /usr/bin/chsh /usr/bin/umount /usr/bin/mount /usr/bin/passwd /usr/bin/newgrp /usr/bin/sudo /usr/bin/chfn /usr/bin/su /usr/bin/gpasswd admin@i-072b43453825ba99a:~$ ./a.out /usr/bin/su